You can access their cryptocurrency if you know those 24 words. They said, is it possible that the hackers have managed to get that for you?
And I said, I think that's really unlikely because I haven't been dumb enough to paste it in anywhere. I have it securely. No, it's not tattooed on my buttocks or anything like that.
Yeah, it's just on the bottom of your website.
Smashing Security, episode 479. How a fake police officer nearly stole Graham's cryptocurrency with Graham Cluley and special guest Danny Palmer.
Hello, hello, and welcome to Smashing Security, episode 479. My name's Graham Cluley.
Now, Danny, I've had a little bit of a run-in with, well, maybe with cybercriminals. I'm not sure. Let me tell you something which happened to me just a few days ago.
I got a phone call from somebody out of the blue, and I thought, I know that phone number. It said 0800 555 111, which is the number of Crimestoppers, of course.
Not that I'm regularly calling up.
Not that you're regularly involved with crime or crime stopping, pans on anyway.
Not that I'm regularly the victim of crime. But anyway, this call came through and it said Crimestoppers. Oh, okay.
So anyway, I took the call and this chap started speaking to me who sounded very much like he could work for the law.
He could be a — and he introduced himself and said he was some sort of detective or something.
Did he sound like Gene Hunt or someone like that?
No, not as obvious as that. No sort of Ashes to Ashes or Life on Mars connection. But no, he said his name was Dave Pullen.
Hello, this is Detective David Pullen here at the Crime Stoppers organisation. And he said he was working on a computer crime case.
And he says, don't be alarmed, he says, you haven't done anything wrong, he said. And he put me at my ease that I wasn't in any trouble myself.
But he said, maybe you can help me with an investigation.
And I thought, well, maybe I can, you know, because I have helped the police before with some computer crime cases investigating various hacking groups.
And I thought, well, it's a little bit unorthodox, but okay, all right. So he wants to talk to me. And he said that they had arrested someone on suspicion of some cybercrimes.
And during the investigation of the digital evidence, they had found some information about me.
They had got my phone number and they'd got my personal email address. And he told me what that was and that was correct.
And he said, and we've also found a scan of your passport and other information as well. And I said, oh, that sounds bad. I said, tell me more.
Yeah. You said, oh, this sounds not great.
No, it doesn't sound great, does it? And he told me the name of the chap who they'd arrested.
And I'm not going to name him here on the podcast because it's quite possible this person is completely innocent.
But he gave me the name of somebody and they said, do you know this person? I said, no, I don't know him.
He said, do you have any reason to think that he might have a vendetta against you? And I said, well, it is possible.
I said, without being big-headed, it is possible he knows me, but I don't know him.
Don't you know who I am? You said—
I said, I didn't quite say, do you know who I am? But I've got a podcast, you know.
But I said, I've been working in cybersecurity for 35 years or whatever and, you know, have a certain prominence. So it is possible.
And I have received threats in the past from criminals. And so it is possible there's been some kind of breach.
And he said, well, have you shared your passport information with anyone?
And I said, well, you know how it is sometimes, you know, I go and give talks around the world and sometimes people are booking me flights and sometimes people do ask for your passport.
So much as I groan about it and grumble and how bloody hell, can this be allowed? And it shouldn't be. And I tried to ensure that they delete it afterwards.
It is possible that a scan of my passport is out there being held by somebody. So I said, yeah, well, it is possible they've got my passport. And they said, okay, all right.
And they said, well, he said you sent it to him because you were booking an Airbnb in Manchester. And I said, no, that's not true. I haven't booked an Airbnb in Manchester.
Well-known tourist destination, Manchester.
Well, you know, I mean, I imagine some people might want an Airbnb. Anyway, I don't have a need for an Airbnb in Manchester.
I believe our Prime Minister is from there.
There's rumours of that I've heard anyway.
Likes to describe himself as King of the North, which I imagine is actually rather upsetting to all the people for whom Manchester is considerably south of.
Anyway, he likes to say that. So they said, okay, well, that's interesting.
They said, now, the other thing is that we have found some evidence that he had collected some information on people who own Trezor hardware wallets, which you can use to store your cryptocurrency on.
And hands up, I think I've spoken about it on the podcast before. I do have one of these hardware wallets for cryptocurrency. I bought it years and years and years ago.
I've only got a very small amount of cryptocurrency. If that weren't the case, then I wouldn't be doing a podcast.
But, you know, I do have one of these wallet things and cybercriminals have found out that I've got one of these. I think at some point the Trezor mailing list was compromised.
Maybe they were using a third party for their newsletters or something.
Maybe it was like Mailchimp or something like that, because they know my email address because practically every day I get a phishing email claiming to come from Trezor, right?
Asking me to do things. And it's like, oh, here we go again.
Persistent, I suppose. There's that at least they've got going for them.
Right. So I thought, okay, it is quite possible that criminals know that I have one of these wallets.
And so he said to me, not only do they know that you have one of these wallets, they also have a 24-word seed key, which of course is the magic combination of words required to unlock someone's wallet so you can access their cryptocurrency if you know those 24 words, right?
They said, is it possible that the hackers have managed to get that for you? Because he appears to have a document which suggests that he's got it.
And I said, I think that's really unlikely, because I haven't been dumb enough to paste it in anywhere. You know, I have it securely.
No, it's not tattooed on my buttocks or anything like that.
It's just on the bottom of your website.
No, no, it's not. Right. So it's a secret. And he said, okay, okay. He said, but if your cryptocurrency were compromised, would that make you suffer a significant financial loss?
And I said, no, it wouldn't because I've hardly got any cryptocurrency. You know, it's really not very much at all. And he sounded a bit disappointed at that point.
And then he said, well, do you have any other cryptocurrency? And I thought, this is all getting a bit strange.
Yeah, this policeman's very interested in the contents of your wallet.
And particularly how much I might have in my cryptocurrency wallet. And so I said to him, I said, can you give me your name again?
And he gave me his name and I quickly had a little look, and sure enough, there he was on LinkedIn and he does appear to work for the police. Thought, interesting.
And I thought, he wouldn't be ringing from Crime Stoppers, would he?
And he said, can you go to a police station within the next 24 hours and take a look at the photograph of the person we've taken into custody to see if you recognise him for any reason?
I said, all right, okay, I could do that. And he said, just head to the main reception desk. And he gave me a crime reference number. And I said, oh, I can go somewhere tomorrow.
I said, I can go to a particular place.
Did they know which police station you'd have to go to?
And this was curious. So he said, is there a police station near you that you can go to? And I thought, I don't want to reveal where I live precisely.
So I gave the name of a town where I didn't live, where I knew there wasn't an open police office or department. And he says, okay. He says, I've just booked you in.
So you can go there, go up to the reception desk, quote this number. And he didn't ask me what county I lived in, for instance.
I just named a place and I thought, wouldn't you ask for some more information?
Anyway, so I began to ask him some questions, whereupon the phone cut off and I thought, that's strange.
And I looked in my email and there was an email claiming to come from the Metropolitan Police telling me that if I did not act upon their email, then potentially action could be taken against me because they said, you have to help us with this criminal.
So there's the email saying you've potentially been a victim of crime.
If you don't help us investigate this crime, you are a criminal as well.
Potentially, yes. They could take action against me. And I looked in the headers of the email and although it had forged the headers, there was information in there.
If you look in the raw header information, it was clear it had come from somewhere else. And I thought, ooh, this is getting quite juicy.
And by this point, of course, I'm really kicking myself because I wish I had said, I've got 4 million quid in my cryptocurrency wallet and wait for them to try and inveigle out of me my 24-word seed key, which surely was the thing that they're gonna do.
So they're gonna say, well, can you read it out to us and we'll compare that to the one we have on our records? I think that was the plan.
I tried to call Crime Stoppers because I thought, well, their phone number's been forged. Couldn't get through to them. Just disaster.
Contacted Action Fraud, which is the thing you are told to do. I don't know what your experience has been reporting crimes to Action Fraud.
They've rather blotted their copybook over the years. They're not the most efficient.
Anyway, utterly unimpressed by their response, which was unhelpful because I shared all the email information and so forth and they just said, well, there's nothing here for us to investigate.
There is stuff here because presumably this person is going through a list of people who they know has Trezor cryptocurrency wallets on the phone, claiming to be the police and trying, I imagine, to get their seed keys out of them.
I did my best, Danny. I did my best. So that has been my unusual experience over the last few days. Once again, I've failed to become a victim of cybercrime.
Whoever the individual or group behind this is, they're putting a lot of effort into this with the time it takes to do the phone calls, the research, that sort of thing.
I mean, they've left some holes in their plan, but yeah, this doesn't sound like it's some sort of amateur operation.
This is a group which seems to have a targeted goal to get this particular account using the information of this particular provider.
So they've got access to that and they're basically going down the list to try and get what they can from people.
It's possible they could — maybe they thought that would be a scalp, which would cause them some amusement.
It felt a little bit like Scattered Spider's tactics of ringing up customer service desks.
I mean, this guy did sound — you know how policemen have a certain timbre? I mean, it sounded like that. You know, it wasn't like, hello, yeah, I am Chief Inspector Morse.
It wasn't like that. You know, it was—
It wasn't 3 12-year-olds in a big coat, no.
Anyway, before we kick off, let's thank this week's wonderful sponsors. Arctic Wolf, NordLayer, and Vanta. We'll be hearing more about them later on in the podcast.
This week on Smashing Security. We won't be talking about how people's Claude chats are turning up in Google search results.
You'll hear no discussion of how Iranian hackers are being blamed for a multi-state cyberattack on US water systems, although Donald Trump is blaming the Democrats.
And we won't even mention how Google Maps allowed anyone for one whole day to fake satellite images of nuclear plants and floods before quietly pulling the feature.
So Danny, what are you going to be talking about this week?
I'm going to be talking a bit about quite a major attack on the Department for Education and how this relates to schools and universities and why they've become prime targets for hackers.
And I'm gonna be checking into a hotel where I'll be having rats with my cornflakes.
All this and much more coming up in this episode of Smashing Security.
Right, before we crack on any further, Joe and I want to take a moment to tell you about one of today's sponsors, Vanta.
We've got a question for you. What's the thing that keeps you staring at the ceiling at 2 AM when it comes to your company security?
Is it wondering whether you've actually got the right controls in place? Whether one of your suppliers has been quietly compromised, or is it the truly soul-destroying one?
Why on earth are we still running our entire security programme out of a spreadsheet?
If any of that hit a little too close to home, that's where Vanta comes in.
Vanta takes all that tedious manual security grind — chasing down evidence, wrestling with questionnaires, updating the same cells for the thousandth time — and automates the whole thing.
Their trust management platform keeps a continuous eye on your systems. It pulls everything into one central place, and keeps your security programme audit-ready around the clock.
Yes, it uses AI, but the genuinely useful kind, flagging risks, streamlining evidence collection, and slotting into the tools your team already relies on.
The upshot of this is you move faster, scale without the usual headaches, and maybe, just, just maybe, actually get a decent night's sleep.
Sounds lush. Find out more and get started at vanta.com/smashing.
That's Vanta.com/smashing. And a big thank you to Vanta for supporting the show. So, chums, you're travelling for work. We've all done it, right? Travel for work. You've had a long day.
Maybe it's been a lengthy trip and you finally made it to your hotel and you dump your bag on the bed, you kick off your shoes, you've opened your laptop.
First thing you're doing, priority number one, connect to the Wi-Fi. And you know how it is connecting to a hotel network.
Normally a little page will pop up asking you, can you confirm your room number? And sometimes they'd ask you for your surname as well.
And you accept their terms and conditions that you're not gonna do anything naughty on the Wi-Fi. And hopefully you're then online. It's fairly painless these days.
I think most hotels have made it a lot easier than it used to be maybe 10 or 15 years ago.
Yeah, we're long past the point of where you have to go through about 5 different websites to get online and pay £20 for the privilege of an hour of internet, as it used to be back then.
So, you know, the job's done.
Except according to security boffins who say for the last few months at least, there is a chance that something else has been happening to travellers logging into their hotel Wi-Fi.
Russia's Foreign Intelligence Service, the SVR, they run a hacking group variously known as APT29, Midnight Blizzard, or Cozy Bear.
They are behind some of the biggest hacks of the last 10 years, including the SolarWinds supply chain attack, the hack of Microsoft's own corporate email, the breach at Hewlett-Packard Enterprise.
So these aren't script kiddies. These are serious cybercriminals with the backing of the Kremlin, professional spies funded by the Russian state.
And apparently they have gone on holiday. Apparently they could be at your local hostel.
Microsoft researchers have called this campaign Captive Crunch. And I have to say, that really tickled me. Why would Captive Crunch tickle me, Danny?
What's your hacking history knowledge?
Sounds very similar to a well-known breakfast cereal.
So in America, I don't know if it's sold here in the UK as well, there is of course the Captain Crunch breakfast cereal. And famously, it was the name of a hacker.
Who I think took the name because he used to freak the phone system by—
Using the little whistle they gave away as a giveaway in a packet of Captain Crunch. That's way back when, decades and decades ago.
Frankly, I'm very impressed at Microsoft. This is probably the best piece of branding their marketing department has done in years, calling this Captive Crunch.
Someone definitely deserves a pay rise. This attack takes advantage of captive portals, which are the pages that help you to log into hotel Wi-Fi.
So when your laptop joins a hotel network via Wi-Fi, it asks the network, where is everything, right? I've joined.
Where can I find stuff? Because I want to go to Google, I want to go to Netflix or iPlayer or whatever it is you want to do.
And one of the things that the network provides is a phone book for the internet, which is the DNS, the Domain Name System, right?
And it's not quite as hefty as Yellow Pages, but—
Right. And this is the thing which translates your entry into your browser of microsoft.com into a sequence of numbers. Websites are actually at numbers, IP addresses.
You don't remember those, so you remember names instead. So you go to microsoft.com or smashingsecurity.com instead.
The point is though, if you connect to someone else's Wi-Fi network, your computer or phone trusts that network's DNS to give it the right answer, not to transmogrify microsoft.com, for instance, into the wrong sequence of numbers.
Because if that were to happen, your browser would be taken to a website and in the browser bar it would still say microsoft.com.
But it would actually be on a different server instead, because you could be phished, malware could be downloaded, you may hand over important credentials.
Yeah, I presume anyone doing this isn't doing it for no particular reason. They have malicious, nefarious goals for doing this.
Yes, it's absolute mischief-making. And so what these Russian hackers have done in this case is they've got into systems that run the hotel or conference centre Wi-Fi networks.
And once they're in there, they mess with the DNS for every single guest simultaneously. So there's no need to touch anyone's individual devices.
There's no need to send any phishing emails. You, the guest, connect to the hotel Wi-Fi.
Your laptop gets pointed at servers controlled by the hackers rather than the one which you intended to actually access instead.
That seems very economical of them. Phishing can be a lot of effort if you go around individuals.
Well, you're saying here, by doing what they're doing, they can get everyone within the hotel, which could be hundreds or maybe thousands of people depending on the size of it.
So are they doing this remotely or is there someone looking suspicious in the cafe on a laptop?
I think this is being done on such a scale that there isn't someone lurking in the ice cream parlour of the hotel.
The boffins at ReliaQuest, they say they have found this at hotels in multiple US cities.
And internationally in Saudi Arabia and India, collecting information from diplomats, government employees, people who work in financial services, legal firms, healthcare, energy, all kinds of people, anyone who travels for work.
So they're not just after holidaymakers, they're going specifically for venues and hotels around them, which are known to be hubs for particularly large events and conferences.
I think so. I think they're thinking that's where the juicy information is rather than the flea pit.
On the dark side of town. They're looking for people who either have money or they have information which would be useful.
Now you might think, well, this is fine, that's not a problem. I'll just hardcode Google's DNS server, which is 8.8.8.8, into my device.
I will bypass whatever DNS the hotel gives me.
But because your DNS request from your phone or from your laptop still leaves your computer as plain readable traffic, the Wi-Fi gateway can intercept it.
Never will go anywhere near Google's DNS. So you ask for Google's opinion, but in fact you get the hacker's answer instead.
It does sound bad. I'll be honest, Graham. It does.
Because you can type in the correct URL of a website, you can choose it from your bookmarks and you'll be taken to a phishing site instead, or your software will be downloading a malicious update maybe.
And it will still look like in the URL bar that you're on the real site. So that would be bad enough, but there's worse.
Oh, because it turns out some of the victims have also been hit by ClickFix attacks. Now, we talked a little bit about ClickFix last week.
Yes, our friend ClickFix.
There's such a wave of these ClickFix things, aren't there?
Anyone who hasn't already heard, just to very quickly describe it, it's where you have a popup or something asking you maybe to confirm that you're a human or to fix a technical problem.
Will you press this sequence of keys, which normally involves Windows+R on your Windows computer. Yeah.
Can you open this on your desktop and paste this code we've conveniently placed in here? Don't ask us what the code is, but just paste it in.
Because you're effectively hacking your computer on behalf of the hackers by running a malicious piece of script.
But because you are doing it, your computer isn't gonna go, oh, hang on, what's going on here? So, oh, it's the operator, the usual user doing this.
So there's no need to question that. Carry on.
And if you fall for that, you've just installed something called Cornflake. Another great name.
This is a Windows remote access Trojan that logs your keystrokes, which means they've got your passwords. It takes screenshots, records your microphone, your webcam.
I mean, what could possibly go wrong in the privacy of your hotel room if your webcam and your microphone are being recorded?
Steals passwords from your browser as well, exfiltrates files. Gives hackers remote access to your computer. And it does all this while disguising itself.
It claims to be a Windows service called Cloud Sync Service. Very sort of generic.
Well, that sounds suitably boring for me to not care about what that is doing on my laptop.
Yeah, it just claims to be a service which is needed to synchronise files with your cloud storage provider.
So people are going to run that, particularly if they're working remotely. They probably want to connect to their cloud storage provider.
Many people think that's innocuous, and so they think there can't be anything dodgy with that. And you might think, well, wouldn't my antivirus spot that? Well, it might.
But this Cornflake thing is very good at maintaining persistence. It's a little bit like a dried cornflake on the bottom of your crockery, right?
You can't necessarily easily get rid of it. So if your antivirus removes it, or you try to remove it manually, it puts itself back.
That's always the tricksy thing with these. I always find interesting about malware and Trojans.
Some of them are so clever, you do everything you want to get rid of it, then it's still — you close your front door, then you turn around and it's there standing right behind you again.
And it doesn't stop there. Running alongside Cornflake is a PowerShell info stealer. Do you want to have any guesses, Danny, as to what this one is called?
Oh, Rice Krispies, Weetos, Red Brick, Shredded Wheat.
This is ChocoShell, apparently. ChocoShell steals your —
That sounds like one of those off-brand ones you get at the discount supermarkets.
It's not Coco Pops.
It's ChocoShell, which steals your Microsoft 365 session tokens, which means if you've got multifactor authentication in place, as you should do, on your Microsoft 365 account, the hackers can still access it using your session token.
And all of this is overseen by a control panel, another piece of software, Fruitstone. Frankly, that doesn't sound that appetising to me.
I think they're running out of ideas now in terms of — so the people who've named these, is it Microsoft who've named these or is it the criminals who've named these this way?
I think it's Microsoft again.
I think it's the engineers there and at Reliant. It's what they get for breakfast when they turn up in the mornings at Redmond.
I think they can't be offering a decent breakfast to the technicians working at these security companies. That is my only explanation.
Fruitstone claims to be something called Cloud Sync Console by a fictional company called Acuity Systems Inc. It's designed to look utterly boring.
As I said, yeah, you can see the offices of this fake company now because I'm seeing a lot of grey. A lot of beige. I'm getting very 1990s vibes from it.
So they don't want to draw attention to themselves. So what can you, dear listener, do about this?
Well, the single most effective thing, if you are a business, if you manage corporate devices, is to enforce the use of a full tunnel VPN.
So it's not the kind of VPN where DNS can sort of sneak out round the edges, but it's properly full tunnel.
All traffic, including DNS requests, goes through your corporate network before it goes anywhere else. Okay. So you're not paying any attention to what the hotel is saying to you.
So if you can do that, that's a great defence.
Okay. For businesses, yes. I struggle to get people I know to even use 2FA or a password that isn't the word password.
Well, maybe not to that extent, but sometimes solutions, because they can be perceived as so complex, people go, ooh, that sounds too complicated.
And they're unfortunately left open to things like this, I suppose.
So there is some advice for individuals as well. You maybe don't have that business solution. What you can do, of course, is you could use your mobile phone as a hotspot.
You could treat hotel Wi-Fi as something to be avoided. If you must use hotel Wi-Fi, you can use a VPN that will give you some protection.
Using a VPN is better than not using a VPN, but don't install anything.
Or if you get one of those click fix messages, if the captive portal asks you to install a driver or if it asks you to cut and paste something, you know, run to the hills effectively.
If there's anything like that.
I don't think my hotels tend to ask me to install something on my computer when I get there.
That's some sound advice.
So next time you're sitting in the hotel room hooking up to the Wi-Fi, just bear in mind you might not be the only one. Getting connected, it could be the hackers as well.
This week's episode is supported by NordLayer.
NordLayer. And before anyone says anything, no, it's not NordVPN.
You were absolutely going to say that, Joe. They are both from Nord Security, but NordLayer is a completely different product. NordVPN is for individuals.
NordLayer is a network security platform built for businesses.
Right, so what does NordLayer actually do?
Well, think about how your team works today. People logging in from home, from hotel Wi-Fi, from coffee shops, from wherever.
From a sun lounger, hopefully.
You'd be lucky. And the moment someone logs into a company network over an unsecured connection, you've got a problem. Credentials intercepted, phishing attacks, unauthorised access.
It's a scary world out there for travelling workers.
It gives you encrypted connectivity for your whole team from anywhere, up to 1 gigabyte per second with zero additional hardware required.
But it goes well beyond just encrypting the connection.
You get centralised control over who can access what based on their identity, their device, whether their device is actually compliant.
And if someone leaves the company, you revoke their access immediately.
No more ex-employees still wandering around your systems 6 months later.
No more of that. And it will block malicious sites, risky downloads, dangerous domains. And it can even detect shadow apps.
So if someone on your team has started using some AI tool that your security team hasn't approved—
Yeah, well, whatever. NordLayer can spot that too. And there's no complex infrastructure to set up. Apparently, you can be up and running in just about 10 minutes.
10 minutes. Plans start from just $8 per user per month. And right now, there is a summer sale. New customers get up to 20% off annual plans until the end of August 2026.
Use the code NLSUMMER26 at checkout.
Whoa, all I have to do is type in that code at nordlayer.com/smashing and I can get a great deal? Let me write that down.
Yep, go ahead, write it down.
What's the code again? I forgot.
Got it. Off to nordlayer.com/smashing I go.
And thanks to NordLayer for supporting the show. Danny, what's your story for us this week?
Well, Graham, it's been a long time since I was at school, and I dunno how much has changed for sure, though I'm pretty sure that laptops and other internet-connected devices are much more commonplace than they were back when I was at school, when the computers were restricted to basically one room in the entire building.
So this was, oh yeah, late '90s, early noughties. Just pre-internet age. The only sort of connected devices, if you can call them that, we had back then was a Tamagotchi.
That was about the most virtual distraction you could get in class pre-smartphone, which not astounds me, but kids these days, he says, sounding like a very old man, they grow up with, you know, internet-connected devices, smartphones, that sort of thing, which we'll get onto in a moment.
But back to school, as it were.
I'm sure that even the best, most student-friendly teacher now or back then would prefer to keep their students at arm's length.
As far as I know, you don't call your teacher by your first name.
I thought you meant like a personal hygiene issue.
Well, that's also bad. But anyway, I digress. But they'll be Mr. Smith or Ms. Jones. You won't really know your teacher's first name. And I suppose Mr. Smith or Ms.
Jones would like to keep it that way. They would not want their information out there for nosy students to find out, 'cause, you know, it's the summer holidays right now.
Kids need stuff to do, and, you know, kids like to find mischief, as far as I understand.
Well, unfortunately for thousands of teachers and headteachers, they have had their names, job titles, and email addresses, and in some cases, phone numbers stolen in a hack, and the crooks behind it have threatened to leak it.
So imagine, for most people, having your personal data stolen is an annoyance, but for a teacher to have their contact details leaked, there's probably some pranksters, ne'er-do-wells who might be tempted to use that for the wrong reasons.
Some kids don't like being taught by teachers, I believe.
But anyway, this is all potential worry, comes back to the UK government's Department for Education, for England specifically, 'cause I believe, you know, Scotland, Wales, Northern Ireland devolved out, which according to the Times revealed recently that hackers had obtained over 600,000 records in a cyberattack.
Now, the use of the word records is important here. It isn't the number of individuals which have been affected by the incident.
No, there aren't hundreds of thousands of teachers which have been affected by that. So I imagine if it was, that's basically every teacher in the country.
But the lines of data which have been stolen in a hack against the Department for Education's help desk portal.
The information on how this attack occurred is still not fully publicly out there, but there seem to be suggestions that it is like you experienced, Graham, sort of social engineering to try and get sort of usernames, passwords, that sort of thing for this help desk portal.
But fortunately for those affected, the theft isn't thought to include bank details or sensitive personal information. So there is that at least.
I don't imagine you want little Jimmy Scrackett, let's say, getting their hands on teachers' bank details, because I'm sure that would be pretty bad. So that's good at least.
So that might be a result of the Department for Education, which said the attack was contained quickly.
So whatever action it had taken, it reduced the amount of data which was accessed and stolen. So thumbs up there. It seems like this attack was spotted fairly swiftly.
It hasn't been going on for a long, long time, we think.
So as any organisation which falls victim to a cyber incident would do, they have got the likes of the National Cyber Security Centre and the National Crime Agency involved.
So those are other arms of the government essentially helping this one investigate.
Are you saying the resources of those investigatory bodies were more preoccupied with 600,000 records of teachers being stolen than they were in me receiving a funny phone call from someone claiming to be a copper?
That's a good point, Graham. Maybe they were.
Have they got their priorities right? I have to ask.
I suppose they might be closer to each other than they are to your house because they ought to be in Whitehall.
They can just walk around the corner to go have a chat, while with you, they'd have to sort of go somewhere else. If it's closer, we'll deal with it. If it isn't, nah, maybe not.
Interestingly though, as a side note, as well as the teachers, there are reports that this incident has also involved details of some police as well, which have been involved as well.
So whole different thing here, but all related to the same incident, which for the government, for the Department for Education, it's likely to be considered something of an embarrassment because it is a major part of the government.
It's been hit by a cyberattack, which is, you know, considering the government, as previously mentioned, government bodies very vocal about the threat of cyberattacks and cyber risk, for them to be targeted by one is, well, probably not unexpected because governments are likely a big scalp, but having been hit by one takes a little bit of explaining, I imagine.
So who is behind this attack?
Well, it's been reported that the culprit is a previously unknown hacking group, which calls itself Exfil Squad, which have been posting snippets of stolen data on their leak site.
There's, again, information about these is patchy, but they sound kind of similar to your Scattered Spider type operation where it seems they've got together to do this, to make money, to cause trouble.
And make money is what they want to do here because according to the Guardian newspaper, these hackers have demanded a payment from the Department of Education not to publish the whole vast swathes of the 600,000 bits of data they have stolen.
It's a familiar story of pay the ransom, otherwise we're going to publish the data which we've stolen from your servers.
Exactly. You know, it's essentially like ransomware tactics, but as appears to be increasingly common for extortion groups, they cut out the middleman, middle software.
The ransomware element of it. They don't encrypt your files. They just go in, steal it, and say, we have it, now pay us.
Which I guess for the attackers takes less time because you're not having to sort of slowly move your way around the network to encrypt everything you need, and probably a bit less effort on their part.
For ransomware, for example, you need to have some ransomware under your belt to sort of shove into the system you're trying to compromise.
Well, if you're stealing data, you can just use a stolen login account. Click fix vulnerabilities, that sort of thing.
So it sounds like it's part of an efficiency drive by the attackers here. Also, there is just the fact that you know many attackers are just lazy.
They want to do the least amount of work possible to make the most money they can, and in this case, just stealing the data is what they're doing.
So they've gone in here and they've stolen this data and threatened to publish it.
The statement which has been posted in the media in articles about this is — the attackers say, and I quote, the payment we request of you is simply a rounding error compared to the litigation costs of your data leaking.
Be smart and just pay. Which is polite, isn't it? I just find it fascinating, these cybercriminal groups, they always try to make it sound like they are doing you a favour.
Like, oh yes. Oh, we discovered your security is terrible. And we'll help you fix it if you pay us money. And if you don't, well, we're just gonna make it even worse. Yes.
You're a client of theirs. They've done some consultancy. You hadn't actually employed them, but they've done some consultancy on your network security.
Yeah. It wouldn't really work the other way.
Imagine going to the supermarket and a shop member of staff threatening you with a big stick if you don't buy a certain product from the shelf.
But that's what they're doing here, essentially.
They've threatened to expose this information about teachers and headteachers, which, as established, isn't the most sort of sensitive information out there, but it would be annoying for those people who are affected, not just because they could become targeted by scams, but also, yeah, there's the potential for mischievous students playing pranks on them, as you imagine they might do.
But in addition to this, this leak has also contained information about members of staff at universities as well.
So they are under the remit of the Department for Education, but this is beyond a bit from your schools and your colleges.
And I'm sure listeners to Smashing Security are likely aware, the university has had something of a torrid time when it comes to cyberattacks this year.
There've been a range of high-profile incidents around the world. Here in the UK, the University of Nottingham received a significant cyberattack where a lot of data was breached.
And it all comes at a time when there's lots of stories in the news about students not being very happy with the services they're getting from university anyway, sometimes because it costs a lot of money.
And if you are not getting your education because someone's ransomwared your university, that's not good for anyone.
So there have been several reports in recent months about a significant rise of extortion attacks like this targeting universities, as well as ransomware attacks against higher education and schools.
So why is this? Well, there's a combination of reasons really. So back when I was at university, again, we've established a long time ago.
Yeah, it was about 10, 20 years after they invented the wheel. I remember. Yeah.
Yes. Got to university on horseback. Yeah. We had internet, but it was really, really restricted.
I couldn't use a connection from my student room to play any online games, which I don't think would go down well these days.
I don't imagine you could tell teenagers getting into university that they can't play Call of Duty or FIFA or whatever it is they play these days.
And we still accessed most resources in paper and book form, which again, suddenly makes me sound really ancient. So fast forward to 2026 and things are very different.
Universities are very, very, very online. They rely on the internet for so many things, which is one of the reasons why they're a top target for attackers.
My contract at Security Magazine has recently ended and I'm back to being a freelancer now. But just before I left, I drafted an interview with Keith Joy.
He's head of technology and digital at the University of Arts London, which is one of the most highly rated arts and creative universities in the world.
He told me that nowadays university networks are set up with the expectation that each individual student will come in with maybe 5 devices connected to the Wi-Fi.
I couldn't even imagine that back when I was at university. You had a laptop and that was it. Put simply, students these days, like many of us, expect to be online all the time.
And these university campuses can be home to tens of thousands of students and staff, of course. They all have usernames, logins, accounts, cloud access, that sort of thing.
So like any other organisation, they will try to put security controls around that.
However, unlike a corporate environment, those laptops that are being used by students — I don't think they would react well saying, "Welcome to university, can we take your laptop?
Because we're going to tell you what you can and can't do on your personal laptop."
We're going to lock it down for you. We're going to take away all the fun stuff.
Yes. But no, they want to take their personal laptops so they can use them in their own time.
Students are online a lot, so there's a lot of risk for social engineering leading to increased risks of cyberattacks.
Cybercriminals know that.
They know the students are very online and they know that because these students are paying a lot to attend universities, these universities also can't be in a position where they can be locked down by ransomware or students feel like they've been let down by their data being breached and stolen, which is why unfortunately it remains extremely common for universities to pay ransom demands to cybercriminal groups.
It's an interesting one. I feel like for all intents and purposes, a university does act quite like a corporate environment.
But as mentioned, you can't have that entirely locked down thing going on, so it's a bit of an open goal.
It's a very difficult situation where you've got potentially thousands of students coming in with, as you mentioned, thousands and thousands of devices connecting to the network.
And it's interesting as well. So when you think about it, a business will have people coming and going every year. For universities, a third of people come and go at the same time.
So you have to have all these new accounts, new setups. That sort of time is probably another big window for attackers as well.
You know, "Oh, welcome to university, click here to sign up" — oh, it's a phishing email.
So yeah, unfortunately extortion, ransomware — these remain big issues for the university sector. Education is struggling with this and still is.
A lot of it comes down to resources. I imagine they're not really thinking about cybersecurity until it's too late. It feels like, as is often the case, this is ongoing.
As I said, there is a ransom demand, but I would be very, very, very, very surprised if the government paid a ransom to some cybercriminals.
I think you're right. I think they are unlikely to. It sounds like the hackers are giving it a good try.
No, it's the school holidays right now. Hopefully some lessons will be learned before the new academic year kicks off in September.
I see what you did there, Danny. Lessons will be learned, you hope.
That's the reporter hack in me, isn't it? Every journalist reporter — essentially some base part of them wants to be a headline writer for The Sun.
Graham, am I right in thinking that Arctic Wolf are sponsoring the show this week?
You are right, Joe.
They've just published a new report, 2026 State of the Cybersecurity Attack Surface, and they analysed over 800,000 real IT assets to find out how exposed organisations actually are.
And I'm guessing everything is hunky-dory?
No, not so much. The reality is they found 1 in 3 IT assets is missing at least one critical security control.
Isn't it just? 10% of assets have no endpoint security at all. 17% are completely invisible to the tools that are supposed to be monitoring them.
So the tools don't even know those assets exist?
Right. Ghost assets wandering around your network unprotected. Unmonitored.
Like a retired geography teacher who's somehow still on the school network.
Nobody added him, nobody removed him, and he's been quietly in there for 11 years downloading maps of Paraguay.
Yeah, yeah, yeah, I guess so, Joe. The point is, your attackers will find him before you do because they are specifically looking for the forgotten, the unpatched, the invisible.
That's the path of least resistance.
So what does the report tell us to actually do about it?
Arctic Wolf's report covers how to prioritise the exposures that actually matter, cut through all that noise, and verify that when you fix something, it actually stays fixed.
And the report is free to download. Free!
I like that. Where do I get it?
smashingsecurity.com/arcticwolf.
That's smashingsecurity.com/arcticwolf. And thanks to Arctic Wolf for supporting the show. And please keep an eye on your IT assets and retired geography teachers.
And welcome back, and you join us at our favourite part of the show, the part of the show that we like to call Pick of the Week. Pick of the Week.
Pick of the Week is the part of the show where everyone chooses something they like.
Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish.
It doesn't have to be security-related necessarily. Well, my pick of the week this week is not security-related.
In fact, my pick of the week this week may not actually be a pick of the week.
My pick of the week may actually be a nitpick of the week.
Did you get a new angry jingle set up for that?
There is a special sound for nitpick of the week, which our listeners are listening to right now. They aren't as common as the picks of the week.
Look, I can say pick of the week and I can say nitpick of the week. Listen to that. Can you tell the difference?
Anyway, I'm a bit of a Doctor Who fan. I may have mentioned it occasionally.
You do surprise me, Graham.
I think you're a bit of a Doctor Who fan too, aren't you, Danny?
Yes, yes. I believe the first time we met in person, we ended up having quite a long discussion about this sort of thing, much to the confusion of the people around us.
Anyway, I was recently made aware of a book which has come out called When I Say Run, Run, which is a book which goes behind the scenes of Doctor Who between 1966 and 1969, which for me, see, I love black and white 1960s Doctor Who.
Classic Doctor Who is what I like. That's when Patrick Troughton, the 2nd Doctor, he was in charge of the TARDIS back then. And this book is written by a guy called Thom Dexter.
And I read a review of it and I thought, this book sounds great. 'Cause I'm interested in all the behind-the-scenes stuff more than the actual programme.
I think I'm more interested in the production of Doctor Who. And I thought, oh, that's really interesting. I hadn't heard about that before.
You want to know what materials those enemies are made out of?
So I thought it'd be interesting because it'd be like a diary of the making of Doctor Who in the late '60s. And I thought, fantastic. So I ordered it.
And it was only after I ordered it that I found that maybe the wool had been pulled over my eyes a little.
Because the author of the book is not Thom Dexter. That is a nom de plume. The actual author of the book is a guy called Adrian Rigglesford.
And he just happens to use the name Thom Dexter now. And if I knew that Adrian Rigglesford had written the book, it's probably quite likely I would have paused before buying it.
Because his is a name that is known to me. Because he's rather a controversial chap. Now—
Is he your sworn enemy? Is that the problem?
He's not. No, I do have a nemesis, but it isn't Adrian Ringle's foot. Well, maybe one day we'll talk about my nemesis.
Well, 1999, Stanley Kubrick, right? Fantastic film director, one of the greatest film directors of all time. He died in 1999.
Six months later in the TV Times, which is not a publication I regularly purchase or indeed have ever purchased in my life, but six months just after the death of Stanley Kubrick, they ran what they called a world-exclusive last interview conducted with Kubrick by Adrian Rigglesford on the set of Eyes Wide Shut.
And this came out. And one of the people who read that interview was Kubrick's personal assistant, who said, hang on a minute, this doesn't seem right to me.
I would surely have known about this interview taking place on the set.
Yeah, you'd think they'd know.
Yeah. And furthermore, he said, these quotes from Stanley Kubrick don't sound like Kubrick at all.
And so he challenged the magazine and the TV Times initially resisted and said, well, the interview was tape recorded, but they never provided a recording.
And eventually TV Times admitted that it had been conned by Rigglesford and they published an apology. It was a completely fantasised fake interview.
And it subsequently emerged because this assistant of Stanley Kubrick dug a little deeper. He obviously had the bit between his teeth.
It emerged that Rigglesford had come out with all kinds of interviews over the years with dead stars of Doctor Who, interviews that no one had ever known had taken place.
But he wrote these articles up of like the long-lost interview with so-and-so, which he claimed to have done.
And these were viewed with some suspicion by fans.
And then he was jailed for stealing 50,000 photos from the Daily Mail photo library and selling them to memorabilia shops in London.
So would this have been physical photos as well?
I think he was actually stealing physical photographic prints from the Daily Mail's library.
50,000 is a lot. Didn't all come out in just one big bag labelled swag, I imagine, but—
So this guy has got a bit of a reputation in Doctor Who fandom. So already being a bit of a Doctor Who nerd, I already knew about him and the controversy around him.
And you would've thought after that run-in, he maybe would've chosen a different career. He would've become a landscape gardener. He would've become a bus conductor.
He would've done something else. But it turns out that he actually threw himself back into Doctor Who fandom, writing stuff but under a different name.
And it's only just been found out. The link has been made. So hang on a minute. Now he's writing books which claim again to be factual reports of Doctor Who in the 1960s.
And this mug here may not have lost his cryptocurrency, but he lost his 15 quid buying a book.
Thinking I could trust it. Now, first of all, the book has got a beautiful cover, right? It's a lovely cover. It's a very nice piece of art.
I'm very impressed by that, by Geoff Cummins. Nothing wrong with him.
At least he's commissioned a proper artist to do the cover then.
Yeah, exactly. They haven't used AI.
And I have enjoyed reading the book, but my experience of the book is soured somewhat by not knowing if I can trust a word of it because of this guy's reputation.
And I'm not saying people can't be rehabilitated, but when it comes to producing something which is a historical document, if you want to be taken seriously for talking about something which happened 60, 70 years ago or more, then I think how you behaved in the past, how you have carried yourself, carries some weight.
And so I'm afraid this book, which is called When I Say Run, Run by Thom Dexter in quotes, has to be my nitpick of the week.
And I also, apparently the publisher knew his real identity.
And they only came clean about it when they were challenged and they said, well, we rigorously checked the content ourselves for factual accuracy.
And you just think, well, today, couldn't you have given me the ability to make an informed decision before buying it? So I'm a bit annoyed about it.
And that is my nitpick of the week.
I've just opened the Wikipedia page for old Adrian and yeah, it's never a good sign when probably half of it is under the banner controversies for someone.
I mean, but no, that is a— that does sound like a really interesting read. It's like yourself, you know, I have an interest in these older ones because I'm such a cool guy.
A few years ago when I got married, part of my stag party was going to Riverside Studios to watch on the big screen some episodes of The Tenth Planet.
So for people who don't know, The Tenth Planet was the last ever episode of William Hartnell, the original Doctor Who, which introduced the Cybermen back when they were Mondasian Cybermen, which is when they had cloth faces rather than being made out of metal.
And wow. That was your stag party.
That's part of my stag party. Yeah. Yeah.
Oh, that sounds brilliant.
No, it was really good. Really good fun. Yeah.
Well, it also reminds me of — it's not so much behind the scenes of scenes, but back when they had the 50th anniversary of Doctor Who, 13 years ago now, whatever it was, they had that drama, BBC drama about the making of Doctor Who.
An Adventure in Space and Time, I think it was called. Yes.
You mentioned the Cybermen with the cloth faces. Remembering that, I think it's based off of an old actual picture from the filming.
He's got a cigarette hanging out his mouth during a break in filming.
But it's always good to see behind the scenes of how things are done, but maybe not so if those behind the scenes looks may or may not be true.
What's your pick of the week, Danny?
My pick of the week is not something very new at all. In fact, it's inspired by something which came out almost 30 years ago. First-person shooter Half-Life.
Half-Life is arguably the game that got me into PC gaming in the first place. So I've spent hours playing and replaying Half-Life and its expansions.
For those who might be thinking, Danny, what are you rabbiting on about?
In Half-Life, you are Gordon Freeman. You are an MIT-educated scientist employed at the Black Mesa Research Facility, which is a high-tech quantum physics and science lab.
An experiment basically goes wrong and it creates something called a resonance cascade, which floods the facility with aliens from another world.
And, oh, we've all had days like that, haven't we?
Yes. Anyway, this week I found myself with an urge to revisit Half-Life, but as you can imagine, as a game which first came out in 1998, looks a bit dated now.
This is where a game called Half-Life: Black Mesa comes in.
It's a fan-made remake of Half-Life by a group called the Crowbar Collective, crowbar being sort of the iconic weapon of Gordon Freeman, which used the updated engine from Half-Life 2, which came along a few years later, and other later games from Valve that make it look more like a modern game.
And it's really, really good. I really enjoy it. And it's a fantastic way to revisit the world of Half-Life. It's an iconic game.
I found it when I was a teenager, when I was coming of age. And it's just been a lot, a lot of fun.
And unlike a lot of games these days, you have to spend hundreds of hours to get to the end. You could probably finish this in about 14, 15 hours maybe.
When you're not 14 and you're 40, you might not have as much time to play these games.
Anyway, so Half-Life: Black Mesa, you can get it from Steam and it only costs about £16.
Yeah, I would say, but Steam being Steam, it'll be in a sale at some point. You'll probably pick it up for a fiver if you wait a couple of months. But that is my pick of the week.
Well, that just about wraps up the show for this week. Thank you so much, Danny, for joining us. Where can folks follow you online and find out what you're up to?
Well, I'm a freelance writer, journalist, et cetera. But no, my LinkedIn is probably the best place to keep up with me. I'm pretty active on Bluesky.
Trying to get back into Mastodon as well. Keep sort of kind of forgetting it's there.
And you can find me, Graham Cluley, on LinkedIn, or you can follow Smashing Security on Bluesky, Reddit, and Mastodon and all those sort of places. I'll be lurking up there too.
And don't forget to ensure you never miss another episode. Follow Smashing Security in your favourite podcast app such as Apple Podcasts, Spotify, and Pocket Casts.
For episode show notes, sponsorship info, guest lists, and the entire back catalogue of 479 episodes, check out smashingsecurity.com. Until next time, cheerio. Bye-bye.
You've been listening to Smashing Security with me, Graham Cluley, and I'm ever so grateful to Danny Palmer for joining us again this week. Thank you, Danny.
And to this episode's sponsors, Arctic Wolf, NordLayer, and Vanta. Now, we all know what's coming up.
It's the bit where I pull out names at random from the hat of Smashing Security Plus supporters over on Patreon. And you know what?
I think this week I'm going to dig deep into the bottom of that. I'm going to pull out some of the very longest-serving supporters of the show.
Some of these fine fellows have been supporting the show for, oh, I don't know, six years or more maybe. So who have we got? Thanks to Dimitri.
That name always arrives with a certain brooding intensity. Richard van Liesen, who I imagine owns a fine art gallery in the Netherlands.
Huge thanks to Dr_Herbalist, who always has his prescription pad open, has terrible handwriting, but knows where his Shift key is.
Scotia, and also the gloriously monikered Jonathan Haddock, who I think I met once. Who else?
Well, cheers to Lisa with an S and Jane with a Y, and also to the Scrabble master Robert Ødegard. He's got vowels going in all directions.
And finally for this week, big love to Just Nate Please, Roy Tate, and Yuri Taraday, rounding things off in magnificent style. You know what, guys? I love you all.
Thank you so much for supporting the show. It means so much to me and it encourages me to make the podcast every week, so thank you for all of your support.
If you would like to be like them, you don't only get the chance for me to make fun of your name and thank you at the end of the show; you also get the episodes ad-free, ooh, and you get them earlier than the general public.
So that's pretty neat, isn't it? If you'd like to join up, just head over to smashingsecurity.com/plus for all of the details. You can also support the show in other ways.
You can like, you can subscribe, you can leave a 5-star review. Let me say that again. You can leave a 5-star review.
Go on, leave a 5-star review wherever you listen, or simply spread the word. Every little bit helps. It makes all the effort worthwhile. And until next week, cheerio. Bye-bye.